I Can SE Clearly Now: Investigating the Effectiveness of GUI-based Symbolic Execution for Software Vulnerability Discovery
Yi Jou Li, Zeming Yu, James Mattei, Ananta Soneji, Zhibo Sun, Ruoyu Wang, Jaron Mink, Daniel Votipka, Tiffany Bao
Abstract
While symbolic execution (SE) can discover software vulnerabilities, it has received limited practical adoption. A key barrier is that SE requires human expertise to understand the program’s state and prioritize paths to analyze. Traditionally, users controlled SE through programmatic API calls, but recent tooling now implements graphical user interfaces (GUI). However, it is unclear how these new features affect human-SE performance. To understand this impact, we conducted a controlled experiment where 24 vulnerability discovery experts were tasked with analyzing a binary using an SE tool with either API or GUI-based features. From this study, we identify (1) experts’ SE process, and (2) the impact of GUI-based features on human-SE performance. Then we propose recommendations to improve SE tool design.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5db7482d-141e-4622-a590-349e97975d71Related papers
- An Observational Investigation of Reverse Engineers' ProcessesDaniel Votipka, Seth M. Rabin, Kristopher K. Micinski, Jeffrey S. Foster et al.USENIX Security 2020
- SymQEMU: Compilation-based symbolic execution for binariesSebastian Poeplau, Aurélien FrancillonNDSS 2021
- Attacker Control and Bug PrioritizationGuilhem Lacombe, Sébastien BardinUSENIX Security 2025
- STASE: Static Analysis Guided Symbolic Execution for UEFI Vulnerability Signature GenerationMd Shafiuzzaman, Achintya Desai, Laboni Sarker, Tevfik BultanASE 2024 · 1 citation
- A Qualitative Analysis of Fuzzer Usability and ChallengesYunze Zhao, Wentao Guo, Harrison Goldstein, Daniel Votipka et al.CCS 2025
